Catch the attacker before the login becomes a breach.
Sophos ITDR monitors Microsoft Entra ID, watches the dark web for stolen credentials, and detects identity attacks, for Sophos XDR and MDR customers. Buy a licence below, or ask us to size it.
Looking for a specific model or SKU? Use the search bar at the top of the page. Or browse the options below.
| Capability | What it does |
|---|---|
| Reduce your identity attack surface | Runs more than 80 identity posture checks on your Microsoft Entra ID environment to find misconfigurations and security gaps, with clear, actionable recommendations. |
| Monitor for stolen credentials | Scans the dark web and breach databases and alerts you when your users' credentials are exposed, before an attacker uses them. |
| Advanced identity detections | Detects kerberoasting, account compromise, stolen credentials, password spray, brute force, and impossible-travel sign-ins, with full MITRE ATT&CK Credential Access coverage. |
| User behaviour analytics | Spots insider threats and anomalous activity early by measuring against what normal looks like for each user, to prevent account takeover and lateral movement. |
| Directory infrastructure protection | Monitors changes and suspicious activity in Active Directory and Entra ID and alerts on modifications that could indicate a domain-takeover attempt. |
| Automated response | Take immediate action: disable accounts, force password resets and MFA re-registration, and isolate the device through Sophos Endpoint. |
What is Sophos ITDR?+
Sophos Identity Threat Detection and Response continuously monitors your environment for identity risks and misconfigurations, scans the dark web for compromised credentials, and detects identity-based attacks. It is built on Secureworks Taegis and integrated into Sophos Fusion for Sophos XDR and MDR customers.
What identity attacks does it detect?+
It detects kerberoasting, account compromise, stolen credentials, password spray, brute force, and impossible-travel sign-ins, with full MITRE ATT&CK Credential Access coverage, plus user behaviour analytics for insider and anomalous activity.
Does it monitor for stolen credentials?+
Yes. It monitors the dark web and breach databases and alerts you when user or system credentials have been exposed.
Which identity provider does it cover?+
It runs more than 80 identity posture checks on Microsoft Entra ID and monitors Active Directory and Entra ID for suspicious changes.
Do I need Sophos XDR or MDR?+
Sophos ITDR is a solution for Sophos XDR and Sophos MDR customers. Tell us what you run and we will confirm the right fit when we quote.

